|
|||||||||||
|
Re: [Users] Static virtual ip address
From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Wed Feb 19 2003 - 17:18:53 EST
Chris Ehlers wrote:
No, kicking out the connection is not the default behaviour. Instead an error message is written to the log that the certificate and with it the ID could not be loaded > Feb 19 17:48:41 VPN2 pluto[2783]: could not open host cert file > '/etc/ipsec.d/certs/test2-cert.pem' #PROBLEM > Feb 19 17:48:41 VPN2 pluto[2783]: added connection description "test2" but the following anonymous connection is created conn test2 right=%any leftsubnet=172.30.0.0/16 rightsubnet=172.30.0.5/32 This means that anyone with a valid certificate issued by a trusted CA can connect when the subnets match this definition. Recommendation: When setting up new connection definitions always check what actually has been loaded, using ipsec auto --status Regards Andreas Andreas Steffen e-mail: andreas.steffen@strongsec.com strongSec GmbH home: http://www.strongsec.com Alter Zürichweg 20 phone: +41 1 730 80 64CH-8952 Schlieren (Switzerland) fax: +41 1 730 80 65 ==========================================[strong internet security]=== _______________________________________________Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Thu Feb 20 06:15:38 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:21 EDT |
||||||||||
|
|||||||||||